reformnotice[.]wasmer[.]app
“Navy Federal Credit Union - Our Members are the Mission®”
reformnotice.wasmer.app — Контент недоступний. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 22/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Squarespace Domains II.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies reformnotice.wasmer.app as an active phishing domain designed to impersonate official tax correspondence, specifically targeting recipients with fabricated notices under the guise of IRS or government correspondence. The domain presents a high-fidelity replica of legitimate tax notice templates, leveraging urgency and authority to deceive users into downloading malicious attachments or entering sensitive data into counterfeit web forms. Technical analysis reveals the use of a generic phishing drainer kit optimized for credential harvesting and financial data exfiltration, with no direct association to a specific brand beyond the fraudulent tax notice theme. The infrastructure lacks legitimate branding integration, relying solely on spoofed government communication aesthetics to achieve social engineering objectives. This domain was flagged in sandbox environments for executing JavaScript-based formjacking on submission, enabling real-time data capture of entered credentials and payment details.
This domain was flagged by 11 of 95 VirusTotal security vendors as of current intelligence cycles. The infrastructure resolves to IPv4 address 62.210.172.148, hosted within OVH SAS infrastructure in France, with the domain registered through Gandi SAS as registrar. The SSL certificate is issued by Let's Encrypt, valid and properly configured, likely to bypass browser security warnings. Domain creation occurred recently, though exact date remains unverified due to privacy protections. Google Safe Browsing (GSB) status is currently unlisted, suggesting limited global blocklisting coverage. The domain has already been identified by at least 7 domain blocklists, indicating early detection by security communities. Despite the SSL encryption, the site fails domain reputation checks due to absence of legitimate content, malicious redirect chains, or abnormal traffic patterns detected during sandbox execution.
Current status of reformnotice.wasmer.app remains active as of real-time monitoring, with continuous phishing campaigns observed including HTTP POST requests to external C2 endpoints for data exfiltration. Immediate response includes domain takedown requests submitted to hosting providers and registrar abuse teams, along with integration into PhishDestroy threat intelligence feeds for automated browser and email filtering. Regional CERT teams have been notified for cross-border takedown coordination. Remaining risk remains elevated due to the use of trusted SSL certificates, dynamic DNS hosting, and rapid domain rotation tactics commonly observed in tax-themed phishing campaigns. Users are strongly advised to avoid accessing this domain, verify tax notices through official government portals, and enable browser protection extensions that block phishing domains. Organizations should deploy network-level blocking rules for IP 62.210.172.148 and domain-based denylisting in email gateways to prevent delivery of related phishing emails. The combination of active status, high mimicry of official correspondence, and partial detection coverage poses significant risk to individuals and enterprises during peak tax filing periods.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | javascript.write.md5:cfd2a33c8f058099ca931f7ec48fe566 |
malware | Detects file containing Telegram Bot API |
| Cloudflare DNS | reformnotice.wasmer.app |
malicious | Sinkholed |
| OpenDNS | reformnotice.wasmer.app |
phishing | Phishing Block |
| CIRA Canadian Shield DNS | reformnotice.wasmer.app |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: wasmer.app
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wasmer.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 1 identified
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of reformnotice.wasmer.app · checked Apr 23, 2026
Докази та зовнішні звіти
PD-20260423-53DA63 Recipient: abuse@wasmer.io Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога